Dismissed
(no matching packages found)
Permalink
CVE-2026-9033
6.0 MEDIUM
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Adjacent (A)
- Attack Complexity (AC): Low (L)
- Attack Requirement (AT): Present (P)
- Privileges Required (PR): None (N)
- User Interaction (UI): None (N)
- Vulnerable System Impact Confidentiality (VC): None (N)
- Vulnerable System Impact Integrity (VI): None (N)
- Vulnerable System Impact Availability (VA): High (H)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Modified Attack Vector (MAV): Adjacent (A)
- Modified Attack Complexity (MAC): Low (L)
- Modified Attack Requirement (MAT): Present (P)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): None (N)
- Modified Vulnerable System Impact Confidentiality (MVC): None (N)
- Modified Vulnerable System Impact Integrity (MVI): None (N)
- Modified Vulnerable System Impact Availability (MVA): High (H)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
- Exploit Maturity (E): Not Defined (X)
Activity log
- Created & dismissed (no matching packages found) suggestion
Unauthenticated Captive Portal Session Termination and Forced Logout in Omada Gateways
An unauthenticated attacker with network access to the captive portal service of an affected device can terminate active captive portal sessions, including forcing logout of specific users or clearing all active sessions. Affected users must re-authenticate to regain access. Successful exploitation may allow termination of individual or all active captive portal sessions, causing temporary service disruption and requiring users to re-authenticate.
References
-
https://www.tp-link.com/us/support/faq/5256/ vendor-advisory
Affected products
ER605 v2
- <2.4.4 Build 20260630 Rel.14398
DR3150 v1
- <1.0.1 Build 20260722 Rel.16854
ER605W v2
- <2.0.4 Build 20260723 Rel.43763
ER706W v1
- <1.2.11 Build 20260723 Rel.41567
ER7206 v2
- <2.3.5 Build 20260625 Rel.43136
ER7406 v1
- <1.3.4 Build 20260625 Rel.43136
ER8411 v1
- <1.4.1 Build 20260708 Rel.64832
DR3650v v1
- <1.2.0 Build 20260630 Rel.83311
ER707-M2 v1
- <1.4.4 Build 20260625 Rel.43063
ER7212PC v2
- <2.4.3 Build 20260722 Rel.40250
ER706W-4G v1
- <1.2.6 Build 20260723 Rel.41321
ER706W-4G v2
- <2.1.11 Build 20260723 Rel.41624
ER7412-M2 v1
- <1.2.0 Build 20260630 Rel.82947
DR3220v-4G v1
- <1.2.0 Build 20260630 Rel.82652
DR3650v-4G v1
- <1.2.0 Build 20260630 Rel.83347
ER706WP-4G v1
- <1.1.11 Build 20260723 Rel.41624
ER701-5G-Outdoor v1
- <1.0.3 Build 20260723 Rel.40931
ER603WP-4G-Outdoor v1
- <1.0.2 Build 20260723 Rel.43271
ER703WP-4G-Outdoor v1
- <1.1.7 Build 20260723 Rel.41712